Re: Multiple 538 and 540 ID's in 2003 server Security Events Log?



During every domain logon from a workstation, the domain controller has to
be contacted several times for several reasons:

LDAP
Shares (Netlogon for logon scripts, sysvol for policies)
etc.

Each connection will cause a 540/538 pair.

In Vista we've added share access auditing and RPC auditing so that you can
see precisely what's being accessed. We've also allowed high-volume events
to be turned off individually or in very small groups, so that for instance
you can generate logon events but suppress logoff events, etc.

Best regards,
Eric

--
This information is provided "AS-IS" with no warranty, and confers no
rights.



"Reluctant Sys-Admin" <ReluctantSysAdmin@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:06D890FE-CF4D-4151-BFED-80DE714D8EF5@xxxxxxxxxxxxxxxx
I have a 2003 Server domain controller and XP workstations. I am trying to
audit when domain users log on and off the domain for the day.

There seem to be multiple 538(successful logoff) and 540(successful logon)
event ID's in the Security Events Log for each user when they log on.
Both
ID's appear again several times when the user logs off. Sometimes the
ID's
appear a few minutes apart for the same actual log on/off event, which
makes
it hard to tell when the event actually occurred. Is there a better way
to
tell conclusively exactly when a user logs on/off the domain?

Thanks!



.



Relevant Pages

  • Re: Auditing Logon Events
    ... > I have just been trying to set up auditing on my 2k DC to log every time a ... > user logs onto the system. ... Account logon events will log every request to the DC for authentication; ...
    (microsoft.public.windows.server.active_directory)
  • Re: Similar User Names - OWA Access
    ... John Doe), so one user logs on as John and the ... I can see this in 5.5 because you entered the alias first (at the big ... orange screen) and then the logon. ...
    (microsoft.public.exchange.misc)
  • Re: Remote Registry
    ... The HKCU key is a child or pseudo hive created when the user logs on. ... You will either have to load each one of these hives individually to make the changes, not a viable option for a large network with many users. ... An easy way would be to have the changes done through the logon mechanism, have a script or batch file do the changes for the users as they logon. ... When i try to connect to a remote registry through regedit.exe and after ...
    (microsoft.public.win2000.registry)
  • Re: winLogon
    ... a user logs into Windows. ... Events include logon, logoff, startup, shutdown, ... > I read that WinLogon triggers notification events, include logon, ...
    (microsoft.public.windowsxp.general)

Loading